What Double Extortion Ransomware Actually Steals
Ransomware used to follow a simple script: attackers encrypted your files, you paid to get them back, and the story ended there. A newly published ransomware prevention guide lays out why that model is outdated. Modern ransomware groups now practice double extortion, meaning they steal sensitive data before they ever encrypt a single file. Only after copying customer records, financial documents, employee data, or intellectual property do they lock the systems down and demand payment.
The theft itself is the leverage. If a victim refuses to pay, attackers threaten to publish the stolen data publicly or sell it to other criminals. That threat applies regardless of whether the organization can restore its systems from backups. The guide's framing is direct: double extortion neutralizes the old advice to "just restore from backup," because the ransom demand is no longer only about getting files back. It is about preventing a data leak that could trigger regulatory fines, lawsuits, and reputational damage that lingers long after systems are back online.
This shift has been building for a while. As covered in a recent look at how ransomware gangs are ditching encryption for extortion entirely, some groups have concluded that stealing data and threatening exposure is more profitable and less risky than the technical work of deploying encryption malware across an entire network. Double extortion sits in the middle of that evolution: attackers still encrypt, but the data theft has become the primary pressure point.
Why Backups No Longer Guarantee Safety
For years, the standard ransomware defense was straightforward: maintain solid backups, and if attackers encrypt your systems, restore from a clean copy and refuse to pay. That advice still matters for operational recovery, but it no longer addresses the full threat. A perfect backup restores your servers. It does nothing to stop attackers from publishing stolen files if you don't pay.
This matters because the financial and legal exposure from a data leak can exceed the cost of downtime itself. Organizations handling health records, financial data, or personal information face notification requirements and potential penalties the moment stolen data is confirmed, whether or not the ransom is ever paid. Backups solve the availability problem. They do not solve the confidentiality problem, and double extortion is built specifically to exploit that gap.
The scale of the threat underscores why this distinction matters. Security researchers tracking the Asia Pacific region reported that Kaspersky blocked 250,000 ransomware attacks across APAC in the first half of 2026, a volume that reflects how routine these attacks have become for organizations of every size, not just large enterprises with dedicated security teams.
Layered Defenses: VPNs, Segmentation, and Access Controls
Because data theft happens before encryption, prevention has to focus on stopping attackers from reaching sensitive data in the first place, not just recovering after the fact. The guide points to a layered approach rather than a single fix.
A VPN is one useful layer, particularly for securing remote access into internal systems so that credentials and traffic between remote employees and company networks aren't exposed on public or unsecured connections. But a VPN alone does not prevent an attacker who has already obtained valid credentials, through phishing or a leaked password, from moving freely once inside the network. That's where network segmentation becomes essential: dividing systems into isolated zones so that a compromised device or account cannot reach every server and database the organization owns. If attackers can't move laterally, they can't stage a mass data theft even after an initial breach.
Access controls round out this layer. Limiting which employees and systems can reach sensitive data, requiring multi-factor authentication, and monitoring for unusual data transfers all reduce the window attackers have to exfiltrate information before anyone notices. None of these measures work as a silver bullet on their own. Together, they raise the cost and difficulty of a successful double extortion attack significantly.
Building an Incident Response Plan Beyond Data Recovery
An incident response plan built only around restoring systems from backup is incomplete for the double extortion era. Organizations need a plan that also addresses what happens if stolen data is confirmed: who determines legal and regulatory notification obligations, how communications with customers and partners are handled, and how the organization decides whether to negotiate at all. These decisions are far harder to make well under pressure during an active incident than they are to plan for in advance.
What This Means For You
Whether you run a small business or manage IT for a larger organization, the practical takeaway is the same: a double extortion ransomware defense strategy can't stop at backups. Data theft prevention deserves the same attention as data recovery. That means securing remote access, segmenting networks so a single compromised account doesn't expose everything, and having a response plan that covers data exposure scenarios, not just downtime.
Key Takeaways
- Assume any ransomware incident may involve data theft, not just encryption, and plan accordingly.
- Treat backups as one layer of defense for system recovery, not a complete solution against extortion.
- Use a VPN to secure remote access, but pair it with network segmentation and strong access controls to limit lateral movement.
- Build an incident response plan that addresses data exposure and notification obligations, not only system restoration.
- Stay informed on how ransomware tactics continue to shift, since attackers regularly adjust their methods as defenses improve.




